S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 4, 2025

CVE-2025-3515 Scanner

CVE-2025-3515 Scanner - Arbitrary File Upload vulnerability in Drag and Drop Multiple File Upload for Contact Form 7

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-3515
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other dangerous file types on the affected site's server, which may make remote code execution possible on the servers that are configured to handle .phar files as executable PHP scripts, particularly in default Apache+mod_php configurations where the file extension is not strictly validated before being passed to the PHP interpreter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Drag and Drop Multiple File Upload for Contact Form 7by glenwpcoder
0
Updated Aug 19, 2026View on NVD →
Detail

The Drag and Drop Multiple File Upload for Contact Form 7 is a WordPress plugin used primarily to enhance the file uploading capabilities of the Contact Form 7 plugin. It is widely used by developers and site administrators to facilitate seamless file uploads by users. This plugin simplifies uploading multiple files through a drag and drop interface. Being popular among WordPress users, it is especially useful for websites requiring user-generated content submissions or contact forms. The plugin is designed to allow customizable file handling, fitting a variety of WordPress site configurations. Its functionality is key for many WordPress-driven sites that depend on user interaction and file exchanges.

The vulnerability present in the Drag and Drop Multiple File Upload for Contact Form 7 plugin is Arbitrary File Upload, which stems from insufficient file type validation. This security flaw permits unauthenticated attackers to upload potentially harmful files, such as .phar files. Such vulnerabilities present a risk of remote code execution if servers are not configured properly to handle such file types. It represents a critical entry point for attackers to exploit server configurations that interpret these files as executable scripts. The absence of stringent validation measures creates an opening that hackers can exploit, especially in standard server setups.

Technically, the vulnerability arises due to a failure in the plugin's file upload process, particularly bypassing the blacklist implemented. Attackers can misuse this feature by uploading .phar file types, which can lead to execution if improperly handled by the server environment. The issue arises because the plugin does not enforce adequate restrictions on file types, allowing the upload of dangerous file formats easily. This flaw is exacerbated in environments using the default Apache+mod_php configuration, where file extension checks are not rigorously enforced. It is triggered by sending a POST request to the plugin, exploiting the lack of comprehensive security checks.

Exploitation of this vulnerability could lead to significant security breaches, including the execution of malicious code on the server. The potential consequences encompass unauthorized access to server resources, data breaches, and further compromise through uploaded malware. Servers may become a vector for attackers to distribute other forms of malware or conduct phishing attacks. Websites affected by this vulnerability may suffer from performance issues or defacement due to the altered codebase. Ultimately, exploiting this flaw can lead to a complete compromise of site integrity and control for malicious actors.

REFERENCES

Solution Advice
  • Update the Drag and Drop Multiple File Upload for Contact Form 7 plugin to the latest version.
  • Ensure that file type validation checks are implemented thoroughly to block malicious file uploads.
  • Configure the server to strictly handle file types, especially those associated with execution risks like .phar files.
  • Regularly review and update server and security configurations to guard against unchecked file type handling.
  • Employ security plugins and monitoring tools to detect and block suspicious activity related to file uploads.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.